Хакеры, взломавшие Electronic Arts, рассказали Motherboard, как они это сделали, и это песня в каждом слове!
A representative for the hackers told Motherboard in an online chat that the process started by purchasing stolen cookies being sold online for $10, and using those to gain access to a Slack channel used by EA. Cookies can save the login details of particular users, and potentially let hackers log into services as that person. In this case, the hackers were able to get into EA's Slack using the stolen cookie. (Although not necessarily connected, in February 2020 Motherboard reported that a group of researchers discovered an ex-engineer had left a list of the names of EA Slack channels in a public facing code repository).
"Once inside the chat we messaged a IT Support members we explain to them we lost our phone at a party last night," the representative said.
The hackers then requested a multifactor authentication token from EA IT support to gain access to EA's corporate network. The representative said this was successful two times.(купили токен за 10 долларов, залогинились с ним в корпоративный Slack, рассказали в чате IT-службе, что потеряли телефон на вечеринке и попросили 2FA-токен для входа в сеть компании)
https://www.vice.com/en/article/7kvkqb/how-ea-games-was-hacked-slack